Microsoft Security, Compliance, and Identity Fundamentals (SC-900)Describe the capabilities of Microsoft Security solutionsHard
A security analyst is investigating an alert indicating a potentially compromised service account in their on-premises Active Directory. They need a solution that can automatically detect suspicious activities related to Active Directory users, entities, and behaviors, such as Golden Ticket attacks or unusual service principal usage. Which Microsoft security solution provides this specialized detection?
- AMicrosoft Defender for Cloud Apps
- BMicrosoft Defender for Endpoint
- CMicrosoft Defender for Office 365
- DMicrosoft Defender for Identity
Show answer & explanationAnswer & explanation
Correct answer: D. Microsoft Defender for Identity
Microsoft Defender for Identity (formerly Azure Advanced Threat Protection or Azure ATP) is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
Why the other options are wrong
- A. Microsoft Defender for Cloud Apps is a CASB for cloud application security, not on-premises Active Directory.
- B. Microsoft Defender for Endpoint focuses on securing devices (endpoints), not specifically Active Directory identity behaviors.
- C. Microsoft Defender for Office 365 protects email and collaboration services, not on-premises Active Directory.
Microsoft Defender for Identity
A cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
- Monitors Active Directory traffic for suspicious behavior
- Detects advanced attacks like Golden Ticket, Pass-the-Hash
- Provides insights into user and entity behavior analytics (UEBA)
Memory trick: Defender for Identity watches the AD tree.